SlideShare ist ein Scribd-Unternehmen logo
1 von 11
Downloaden Sie, um offline zu lesen
Service	
  Layer	
  
Help	
  Layer	
  
Customer	
  Layer	
  
Browser	
  
	
  
www.Help.gv.at	
  Portal	
  
	
  
MOA-­‐ID	
  STORK	
   MOCCA	
  STORK	
  
eDelivery	
   eSafe	
   HV-­‐Services	
  
CiDzen	
  
MOCCA	
  
Server	
  
MOA-­‐ID	
  
Server	
  
Graphics	
  
Internet	
  
Internet	
  
eDelivery	
   eSafe	
   HV-­‐Services	
  
26.05.13	
   1	
  
Proxy	
  AuthenDcator	
  
eGovernment	
  official	
  
Channel	
  InformaDon	
  	
  
Help.gv.at:	
  Login	
  via	
  Mobile	
  
26.05.13	
   2	
  
eGovernment	
  official	
  
Channel	
  InformaDon	
  	
  
Customer	
  Layer	
  
myHelp	
  Layer	
  
Service	
  Layer	
  
Browser	
  
eDelivery	
   eSafe	
   HV-­‐Services	
  
MOA-­‐ID	
  STORK	
   MOCCA	
  STORK	
   MOA-­‐ID	
  STORK	
   MOCCA	
  STORK	
  
CerDficate	
  &	
  
Private	
  Key	
  
in	
  accordance	
  
to	
  §35	
  ZustG	
  
in	
  Austria	
  
CiDzen	
  
MOCCA	
  
Server	
  
MOA-­‐ID	
  
Server	
  
Graphics	
  
eDelivery,	
  eSave,	
  HV-­‐Services	
  
	
  CerDficate	
  	
  GeneraDon	
  (pkcs12	
  Container)	
  
‚	
  [RegistraDon/Re-­‐entry	
  (a^er	
  First	
  
RegistraDon)]	
  opDonal	
  
CerDficate	
  
Private	
  Key	
  
1	
  
2	
  
CerDficate	
  GeneraDon	
  
Internet	
  
Internet	
  
1	
  
2	
  
26.05.13	
   3	
  
	
  
www.myHelp.gv.at	
  Portal	
  
	
  
MOA-­‐ID	
  STORK	
   MOCCA	
  STORK	
  
eSafe	
   HV-­‐Services	
  
CerDficate	
  &	
  	
  
Private	
  Key	
  
1	
  
eDelivery	
  
2	
  1	
  
BRZ	
  eDelivery	
  Service:	
  Create	
  CerDficate	
  
26.05.13	
   4	
  
BRZ	
  eDelivery	
  Service:	
  pkcs12	
  Container	
  saved	
  	
  
26.05.13	
   5	
  
Help.gv.at:	
  Connect	
  to	
  BRZ	
  eDelivery	
  Service	
  
26.05.13	
   6	
  
BRZ	
  eDelivery	
  Service	
  
Service	
  Domain	
  myHelp	
  Domain	
  
	
  
Private	
  User	
  Domain	
  
Domain	
  Model:	
  Login	
  Request	
  
26.05.13	
   7	
  
CiDzen‘s	
  Client	
  
Proxy	
  AuthenDcator	
  
(Client	
  Proxy)	
  
myHelp.gv.at	
  
Key	
  
Share	
  
Holder	
  1	
  
BRZ	
  
login	
  page,	
  …	
  
eDelivery	
  Service	
  
meinBrief	
  
login	
  page,	
  …	
  
eDelivery	
  Service	
  
Post	
  Server	
  
login	
  page,	
  …	
  
eDelivery	
  Service	
  
Key	
  
Share	
  
Holder	
  n	
  
1. URL	
  
2. request	
  login	
  
shared	
  Key	
  n	
  shared	
  Key	
  1	
  
shared	
  Key	
  	
  	
  request	
  
shared	
  	
  	
  Key	
  1-­‐n	
  
BRZ	
  eDelivery	
  Service:	
  Upload	
  pkcs12	
  Container	
  
26.05.13	
   8	
  
BRZ	
  eDelivery	
  Service:	
  Show	
  Inbox	
  (2	
  Objects)	
  
26.05.13	
   9	
  
Sequence	
  Diagram	
  Data	
  Access	
  
CiDzen	
   myHelp	
   ProxyAuthenDcator	
   KeySharholder	
  1	
   KeySharholder	
  n	
   Database	
   meinBrief	
  
getData	
  
validaDon	
  <	
  
<	
  
<	
  
<	
  
getData	
  
getSharedKeyPart	
  1	
  
getSharedKeyPart	
  n	
  
validaDon	
  
<	
   reconstructSharedKey	
  
<	
  
loadPrivateKey	
  +	
  CerDficate	
  
<	
   decryptPrivateKey	
  +	
  CerDficate	
  
	
  <	
   connect	
  
Post	
  Server	
  
BRZ	
  
eDeliveryService	
  
26.05.13	
   10	
  
Components	
  for	
  secure	
  saving	
  of	
  the	
  	
  
eDelivery	
  CerDficates	
  in	
  myHelp.gv.at	
  
Key	
  Upload	
  
Policy	
  Server	
  
LDAP	
  
MeinBrief	
  
eDelivery	
  Service	
  
load	
  
access	
  Data	
  
Key1	
  Access	
  
(eDelivery	
  
Correspondence)	
  
myHelp.gv.at	
  
load	
  CerDficate	
  
+	
  Policy	
  Key	
  
Site	
  Minder	
  (AuthenDcaDon)	
  
store	
  
CerDficate	
  
+	
  Policy	
  Key	
  
store	
  
get	
  Key2+Key3	
  
Key3	
  
upload	
  CerDficate	
  
+	
  Private	
  	
  Key	
  
MySQL	
  
Post	
  Server	
  
eDelivery	
  Service	
  
BRZ	
  
eDelivery	
  Service	
  
Key2	
  
based	
  on	
  (bPK+Key2+Key3)	
  
26.05.13	
   11	
  

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

How to integrate bit coin wallet using blockchain methodology
How to integrate bit coin wallet using blockchain methodologyHow to integrate bit coin wallet using blockchain methodology
How to integrate bit coin wallet using blockchain methodology
 
Bitmark and Hyperledger Workshop: the Digital Assets and Property
Bitmark and Hyperledger Workshop: the Digital Assets and PropertyBitmark and Hyperledger Workshop: the Digital Assets and Property
Bitmark and Hyperledger Workshop: the Digital Assets and Property
 
SingularityNET Developer Workshop
SingularityNET Developer Workshop SingularityNET Developer Workshop
SingularityNET Developer Workshop
 
Learning Solidity
Learning SolidityLearning Solidity
Learning Solidity
 
MongDB Mobile: Bringing the Power of MongoDB to Your Device
MongDB Mobile: Bringing the Power of MongoDB to Your DeviceMongDB Mobile: Bringing the Power of MongoDB to Your Device
MongDB Mobile: Bringing the Power of MongoDB to Your Device
 
Introduction to Ethereum
Introduction to EthereumIntroduction to Ethereum
Introduction to Ethereum
 
JWT SSO Inbound Authenticator
JWT SSO Inbound AuthenticatorJWT SSO Inbound Authenticator
JWT SSO Inbound Authenticator
 
MongoDB Mobile: Bringing the Power of MongoDB to Your Device
MongoDB Mobile: Bringing the Power of MongoDB to Your DeviceMongoDB Mobile: Bringing the Power of MongoDB to Your Device
MongoDB Mobile: Bringing the Power of MongoDB to Your Device
 
Architecture of the Hyperledger Blockchain Fabric - Christian Cachin - IBM Re...
Architecture of the Hyperledger Blockchain Fabric - Christian Cachin - IBM Re...Architecture of the Hyperledger Blockchain Fabric - Christian Cachin - IBM Re...
Architecture of the Hyperledger Blockchain Fabric - Christian Cachin - IBM Re...
 
Secure Spring Boot Microservices with Keycloak
Secure Spring Boot Microservices with KeycloakSecure Spring Boot Microservices with Keycloak
Secure Spring Boot Microservices with Keycloak
 
Create and Deploy your ERC20 token with Ethereum
Create and Deploy your ERC20 token with EthereumCreate and Deploy your ERC20 token with Ethereum
Create and Deploy your ERC20 token with Ethereum
 
[FOSDEM 2019] LemonLDAP::NG 2.0
[FOSDEM 2019] LemonLDAP::NG 2.0[FOSDEM 2019] LemonLDAP::NG 2.0
[FOSDEM 2019] LemonLDAP::NG 2.0
 
Hyperledger Fabric and Tools
Hyperledger Fabric and ToolsHyperledger Fabric and Tools
Hyperledger Fabric and Tools
 
[WSO2Con USA 2018] Managing Transactions in Your Microservice Architecture
[WSO2Con USA 2018] Managing Transactions in Your Microservice Architecture[WSO2Con USA 2018] Managing Transactions in Your Microservice Architecture
[WSO2Con USA 2018] Managing Transactions in Your Microservice Architecture
 
Blockchain for creative content - What we do in LikeCoin
Blockchain for creative content - What we do in LikeCoinBlockchain for creative content - What we do in LikeCoin
Blockchain for creative content - What we do in LikeCoin
 
以太坊代幣付款委託 @ Open Source Developer Meetup #12
以太坊代幣付款委託 @ Open Source Developer Meetup #12以太坊代幣付款委託 @ Open Source Developer Meetup #12
以太坊代幣付款委託 @ Open Source Developer Meetup #12
 
Luniverse Partners Day - Jay
Luniverse Partners Day - JayLuniverse Partners Day - Jay
Luniverse Partners Day - Jay
 
Blockchain Explored: A technical deep-dive
Blockchain Explored: A technical deep-diveBlockchain Explored: A technical deep-dive
Blockchain Explored: A technical deep-dive
 
Technical Introduction to Hyperledger Fabric v1.0
Technical Introduction to Hyperledger Fabric v1.0Technical Introduction to Hyperledger Fabric v1.0
Technical Introduction to Hyperledger Fabric v1.0
 
Les mécanismes et protocoles d’authentification sans mot de passe avec Window...
Les mécanismes et protocoles d’authentification sans mot de passe avec Window...Les mécanismes et protocoles d’authentification sans mot de passe avec Window...
Les mécanismes et protocoles d’authentification sans mot de passe avec Window...
 

Andere mochten auch (7)

The ruling of the German Federal Constitutional Court and its technical conse...
The ruling of the German Federal Constitutional Court and its technical conse...The ruling of the German Federal Constitutional Court and its technical conse...
The ruling of the German Federal Constitutional Court and its technical conse...
 
Anneke Zuiderwijk, Marijn Janssen, Keith Jeffery: Towards an e-infrastructure...
Anneke Zuiderwijk, Marijn Janssen, Keith Jeffery: Towards an e-infrastructure...Anneke Zuiderwijk, Marijn Janssen, Keith Jeffery: Towards an e-infrastructure...
Anneke Zuiderwijk, Marijn Janssen, Keith Jeffery: Towards an e-infrastructure...
 
Vasily Bunakov, Keith Jeffery: Licence management for Public Sector Information
Vasily Bunakov, Keith Jeffery: Licence management for Public Sector InformationVasily Bunakov, Keith Jeffery: Licence management for Public Sector Information
Vasily Bunakov, Keith Jeffery: Licence management for Public Sector Information
 
Svenson Jakob
Svenson JakobSvenson Jakob
Svenson Jakob
 
Bürgerforum Europa
Bürgerforum EuropaBürgerforum Europa
Bürgerforum Europa
 
AIRSHOW REVIEW MAGAZINE, Issue August - September, 2014
AIRSHOW REVIEW MAGAZINE, Issue August -  September, 2014AIRSHOW REVIEW MAGAZINE, Issue August -  September, 2014
AIRSHOW REVIEW MAGAZINE, Issue August - September, 2014
 
Irmgard Wetzstein, Peter Leitner: Social media analytics for sustainable migr...
Irmgard Wetzstein, Peter Leitner: Social media analytics for sustainable migr...Irmgard Wetzstein, Peter Leitner: Social media analytics for sustainable migr...
Irmgard Wetzstein, Peter Leitner: Social media analytics for sustainable migr...
 

Ähnlich wie Klaus John, Proxy Authenticator Approach of a Signature based Single Sign on Proxy Solution for e-­‐Government Applications

HashiTalks France 2023 - Sécurisez la distribution automatique de vos certif...
HashiTalks France 2023 - Sécurisez la distribution automatique de vos certif...HashiTalks France 2023 - Sécurisez la distribution automatique de vos certif...
HashiTalks France 2023 - Sécurisez la distribution automatique de vos certif...
Stéphane Este-Gracias
 

Ähnlich wie Klaus John, Proxy Authenticator Approach of a Signature based Single Sign on Proxy Solution for e-­‐Government Applications (20)

Consul: Service Mesh for Microservices
Consul: Service Mesh for MicroservicesConsul: Service Mesh for Microservices
Consul: Service Mesh for Microservices
 
Operationalizing Multi Cluster Istio_ Lessons Learned and Developing Ambient ...
Operationalizing Multi Cluster Istio_ Lessons Learned and Developing Ambient ...Operationalizing Multi Cluster Istio_ Lessons Learned and Developing Ambient ...
Operationalizing Multi Cluster Istio_ Lessons Learned and Developing Ambient ...
 
Consul Connect - EPAM SEC - 22nd september 2018
Consul Connect - EPAM SEC - 22nd september 2018Consul Connect - EPAM SEC - 22nd september 2018
Consul Connect - EPAM SEC - 22nd september 2018
 
SSL/TLS for Mortals (J-Fall)
SSL/TLS for Mortals (J-Fall)SSL/TLS for Mortals (J-Fall)
SSL/TLS for Mortals (J-Fall)
 
Ria Spring Blaze Ds
Ria Spring Blaze DsRia Spring Blaze Ds
Ria Spring Blaze Ds
 
Net Services
Net ServicesNet Services
Net Services
 
apidays LIVE Paris - Multicluster Service Mesh in Action by Denis Jannot
apidays LIVE Paris - Multicluster Service Mesh in Action by Denis Jannotapidays LIVE Paris - Multicluster Service Mesh in Action by Denis Jannot
apidays LIVE Paris - Multicluster Service Mesh in Action by Denis Jannot
 
OpenID 4 Verifiable Credentials + HAIP (Update)
OpenID 4 Verifiable Credentials + HAIP (Update)OpenID 4 Verifiable Credentials + HAIP (Update)
OpenID 4 Verifiable Credentials + HAIP (Update)
 
SSL/TLS for Mortals (GOTO Berlin)
SSL/TLS for Mortals (GOTO Berlin)SSL/TLS for Mortals (GOTO Berlin)
SSL/TLS for Mortals (GOTO Berlin)
 
SSL/TLS for Mortals (JavaZone)
SSL/TLS for Mortals (JavaZone)SSL/TLS for Mortals (JavaZone)
SSL/TLS for Mortals (JavaZone)
 
1205 bhat pdf-ssl
1205 bhat pdf-ssl1205 bhat pdf-ssl
1205 bhat pdf-ssl
 
Building and deploying microservices with event sourcing, CQRS and Docker (Me...
Building and deploying microservices with event sourcing, CQRS and Docker (Me...Building and deploying microservices with event sourcing, CQRS and Docker (Me...
Building and deploying microservices with event sourcing, CQRS and Docker (Me...
 
Configuring kerberos based sso in weblogic
Configuring kerberos based sso in weblogicConfiguring kerberos based sso in weblogic
Configuring kerberos based sso in weblogic
 
Auth proxy pattern on Kubernetes
Auth proxy pattern on KubernetesAuth proxy pattern on Kubernetes
Auth proxy pattern on Kubernetes
 
Plan B: Service to Service Authentication with OAuth
Plan B: Service to Service Authentication with OAuthPlan B: Service to Service Authentication with OAuth
Plan B: Service to Service Authentication with OAuth
 
BYOIDaaS - Automating IAM Infrastructure & Operations
BYOIDaaS - Automating IAM Infrastructure & OperationsBYOIDaaS - Automating IAM Infrastructure & Operations
BYOIDaaS - Automating IAM Infrastructure & Operations
 
HashiTalks France 2023 - Sécurisez la distribution automatique de vos certif...
HashiTalks France 2023 - Sécurisez la distribution automatique de vos certif...HashiTalks France 2023 - Sécurisez la distribution automatique de vos certif...
HashiTalks France 2023 - Sécurisez la distribution automatique de vos certif...
 
Brocade AWS user group Sydney presentation
Brocade AWS user group Sydney presentationBrocade AWS user group Sydney presentation
Brocade AWS user group Sydney presentation
 
(MBL311) NEW! AWS IoT: Securely Building, Provisioning, & Using Things
(MBL311) NEW! AWS IoT: Securely Building, Provisioning, & Using Things(MBL311) NEW! AWS IoT: Securely Building, Provisioning, & Using Things
(MBL311) NEW! AWS IoT: Securely Building, Provisioning, & Using Things
 
SQL Server Security And Encryption
SQL Server Security And EncryptionSQL Server Security And Encryption
SQL Server Security And Encryption
 

Mehr von Danube University Krems, Centre for E-Governance

Mehr von Danube University Krems, Centre for E-Governance (20)

Smart Cities workshop at CeDEM17
Smart Cities workshop at CeDEM17Smart Cities workshop at CeDEM17
Smart Cities workshop at CeDEM17
 
#CeDEM17 - Towards an Open Data based ICT Reference Architecture for Smart Ci...
#CeDEM17 - Towards an Open Data based ICT Reference Architecture for Smart Ci...#CeDEM17 - Towards an Open Data based ICT Reference Architecture for Smart Ci...
#CeDEM17 - Towards an Open Data based ICT Reference Architecture for Smart Ci...
 
#CeDEM17 - Financial Payments and Smart Cities
#CeDEM17 - Financial Payments and Smart Cities #CeDEM17 - Financial Payments and Smart Cities
#CeDEM17 - Financial Payments and Smart Cities
 
#CeDEM2017 Smart Cities of Self-Determined Data Subjects
#CeDEM2017 Smart Cities of Self-Determined Data Subjects#CeDEM2017 Smart Cities of Self-Determined Data Subjects
#CeDEM2017 Smart Cities of Self-Determined Data Subjects
 
Open Data as Enabler of Public Service Co-creation: Exploring the Drivers and...
Open Data as Enabler of Public Service Co-creation:Exploring the Drivers and...Open Data as Enabler of Public Service Co-creation:Exploring the Drivers and...
Open Data as Enabler of Public Service Co-creation: Exploring the Drivers and...
 
DatalEt-Ecosystem Provider - The DEEP project
DatalEt-Ecosystem Provider - The DEEP projectDatalEt-Ecosystem Provider - The DEEP project
DatalEt-Ecosystem Provider - The DEEP project
 
Towards Open Justice: ICT acceptance in the Greek justice system
Towards Open Justice: ICT acceptance in the Greek justice systemTowards Open Justice: ICT acceptance in the Greek justice system
Towards Open Justice: ICT acceptance in the Greek justice system
 
[X]CHANGING PERSPECTIVES
[X]CHANGING PERSPECTIVES[X]CHANGING PERSPECTIVES
[X]CHANGING PERSPECTIVES
 
Using fuzzy cognitive maps as decision support tool for smart cities goraczek
Using fuzzy cognitive maps as decision support tool for smart cities  goraczekUsing fuzzy cognitive maps as decision support tool for smart cities  goraczek
Using fuzzy cognitive maps as decision support tool for smart cities goraczek
 
Understanding of smartphone divide dal yong
Understanding of smartphone divide  dal yongUnderstanding of smartphone divide  dal yong
Understanding of smartphone divide dal yong
 
The motivations behind open access publishing judith schossboeck
The motivations behind open access publishing  judith schossboeckThe motivations behind open access publishing  judith schossboeck
The motivations behind open access publishing judith schossboeck
 
Social media as hobed of racism and hate speech kobayashi, kaigo, kwak
Social media as hobed of racism and hate speech kobayashi, kaigo, kwakSocial media as hobed of racism and hate speech kobayashi, kaigo, kwak
Social media as hobed of racism and hate speech kobayashi, kaigo, kwak
 
Social media and citizen engagement in asia skoric
Social media and citizen engagement in asia  skoricSocial media and citizen engagement in asia  skoric
Social media and citizen engagement in asia skoric
 
Realizin modeling and evaluation city's enerfy efficiency leonidas anthopoulos
Realizin modeling and evaluation city's enerfy efficiency leonidas anthopoulosRealizin modeling and evaluation city's enerfy efficiency leonidas anthopoulos
Realizin modeling and evaluation city's enerfy efficiency leonidas anthopoulos
 
Post 2015 paris c limate conference politics on the internet manuela hartwig
Post 2015 paris c limate conference politics on the internet  manuela hartwigPost 2015 paris c limate conference politics on the internet  manuela hartwig
Post 2015 paris c limate conference politics on the internet manuela hartwig
 
Open government and national sovereignty ivo babaja
Open government and national sovereignty  ivo babajaOpen government and national sovereignty  ivo babaja
Open government and national sovereignty ivo babaja
 
Health r isk communication in the digital era myojung chung
Health r isk communication in the digital era myojung chungHealth r isk communication in the digital era myojung chung
Health r isk communication in the digital era myojung chung
 
An analysis of japanese local government facebook profiles muneo kaigo
An analysis of japanese local government facebook profiles muneo kaigoAn analysis of japanese local government facebook profiles muneo kaigo
An analysis of japanese local government facebook profiles muneo kaigo
 
GovCamp 2016 - Co-Creation
GovCamp 2016 - Co-CreationGovCamp 2016 - Co-Creation
GovCamp 2016 - Co-Creation
 
Datenschutzbeauftragte werden in Zukunft eine wichtige Rolle im Unternehmen s...
Datenschutzbeauftragte werden in Zukunft eine wichtige Rolle im Unternehmen s...Datenschutzbeauftragte werden in Zukunft eine wichtige Rolle im Unternehmen s...
Datenschutzbeauftragte werden in Zukunft eine wichtige Rolle im Unternehmen s...
 

Kürzlich hochgeladen

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Kürzlich hochgeladen (20)

EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNavi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 

Klaus John, Proxy Authenticator Approach of a Signature based Single Sign on Proxy Solution for e-­‐Government Applications

  • 1. Service  Layer   Help  Layer   Customer  Layer   Browser     www.Help.gv.at  Portal     MOA-­‐ID  STORK   MOCCA  STORK   eDelivery   eSafe   HV-­‐Services   CiDzen   MOCCA   Server   MOA-­‐ID   Server   Graphics   Internet   Internet   eDelivery   eSafe   HV-­‐Services   26.05.13   1   Proxy  AuthenDcator   eGovernment  official   Channel  InformaDon    
  • 2. Help.gv.at:  Login  via  Mobile   26.05.13   2   eGovernment  official   Channel  InformaDon    
  • 3. Customer  Layer   myHelp  Layer   Service  Layer   Browser   eDelivery   eSafe   HV-­‐Services   MOA-­‐ID  STORK   MOCCA  STORK   MOA-­‐ID  STORK   MOCCA  STORK   CerDficate  &   Private  Key   in  accordance   to  §35  ZustG   in  Austria   CiDzen   MOCCA   Server   MOA-­‐ID   Server   Graphics   eDelivery,  eSave,  HV-­‐Services     CerDficate    GeneraDon  (pkcs12  Container)   ‚  [RegistraDon/Re-­‐entry  (a^er  First   RegistraDon)]  opDonal   CerDficate   Private  Key   1   2   CerDficate  GeneraDon   Internet   Internet   1   2   26.05.13   3     www.myHelp.gv.at  Portal     MOA-­‐ID  STORK   MOCCA  STORK   eSafe   HV-­‐Services   CerDficate  &     Private  Key   1   eDelivery   2  1  
  • 4. BRZ  eDelivery  Service:  Create  CerDficate   26.05.13   4  
  • 5. BRZ  eDelivery  Service:  pkcs12  Container  saved     26.05.13   5  
  • 6. Help.gv.at:  Connect  to  BRZ  eDelivery  Service   26.05.13   6   BRZ  eDelivery  Service  
  • 7. Service  Domain  myHelp  Domain     Private  User  Domain   Domain  Model:  Login  Request   26.05.13   7   CiDzen‘s  Client   Proxy  AuthenDcator   (Client  Proxy)   myHelp.gv.at   Key   Share   Holder  1   BRZ   login  page,  …   eDelivery  Service   meinBrief   login  page,  …   eDelivery  Service   Post  Server   login  page,  …   eDelivery  Service   Key   Share   Holder  n   1. URL   2. request  login   shared  Key  n  shared  Key  1   shared  Key      request   shared      Key  1-­‐n  
  • 8. BRZ  eDelivery  Service:  Upload  pkcs12  Container   26.05.13   8  
  • 9. BRZ  eDelivery  Service:  Show  Inbox  (2  Objects)   26.05.13   9  
  • 10. Sequence  Diagram  Data  Access   CiDzen   myHelp   ProxyAuthenDcator   KeySharholder  1   KeySharholder  n   Database   meinBrief   getData   validaDon  <   <   <   <   getData   getSharedKeyPart  1   getSharedKeyPart  n   validaDon   <   reconstructSharedKey   <   loadPrivateKey  +  CerDficate   <   decryptPrivateKey  +  CerDficate    <   connect   Post  Server   BRZ   eDeliveryService   26.05.13   10  
  • 11. Components  for  secure  saving  of  the     eDelivery  CerDficates  in  myHelp.gv.at   Key  Upload   Policy  Server   LDAP   MeinBrief   eDelivery  Service   load   access  Data   Key1  Access   (eDelivery   Correspondence)   myHelp.gv.at   load  CerDficate   +  Policy  Key   Site  Minder  (AuthenDcaDon)   store   CerDficate   +  Policy  Key   store   get  Key2+Key3   Key3   upload  CerDficate   +  Private    Key   MySQL   Post  Server   eDelivery  Service   BRZ   eDelivery  Service   Key2   based  on  (bPK+Key2+Key3)   26.05.13   11